DOJ Seizes Web Domains Used in Chinese Cyber Intrusion Campaign Against U.S. Agencies and Infrastructure
Federal authorities dismantled infrastructure supporting malware platforms that targeted the Federal Reserve, NASA, telecom networks, and financial institutions.

Federal law enforcement agencies have seized web domains tied to two specialized hacking tools used in state-sponsored cyber intrusions targeting high-profile U.S. government bodies and critical commercial sectors, according to court documents unsealed Wednesday. The operation rendered inoperable infrastructure that had been deployed against institutions including the Federal Reserve, the Department of Justice, NASA, and the U.S. Senate.
Beyond public sector bodies, the breach attempts extended across major commercial categories. Court filings indicate that malicious activities conducted through the platforms impacted telecommunications providers, financial institutions, health systems, utility operators, and defense contractors. The Department of Energy, the Department of Health and Human Services, and the National Institutes of Health were also listed among affected government targets.
The court-ordered domain takedowns effectively neutralized two primary malware platforms, identified in legal filings as "QScan" and "QTRouter." Because the seized web domains were hard-coded directly into the underlying software, seizing control of the addresses made both hacking systems fully inoperable, according to federal officials.
Records unsealed in U.S. District Court for the Southern District of California attribute the creation and deployment of the hacking platforms to a Chinese state-backed entity known as "QTFY." The threat collective was operated under the auspices of Nanjing Xinjiuwei Network Technology Co., a technology firm based in China.
Federal prosecutors reported that QTFY's commercial clientele included the People's Republic of China's Ministry of State Security as well as the People's Liberation Army. The Justice Department did not outline the extent of systemic damage or specific data exfiltrated during the intrusions.
"State-sponsored malicious hackers preying on America's critical infrastructure will be stopped and prosecuted. We are here to ensure security for the American people and will use every tool we have to keep that promise," U.S. Attorney General Todd Blanche said in a statement Wednesday. Blanche added that federal law enforcement successfully "investigated and disabled the PRC's malicious software, the latest in a series of technical operations to dismantle indiscriminate hacking activities sponsored by the People's Republic of China."
As first reported by CNBC Business, federal authorities did not elaborate on specific remediation timelines, and the Chinese Embassy in Washington, D.C., was contacted for comment regarding the court filings.
The domain seizures follow recent criminal enforcement involving Chinese intelligence access to federal policy channels. A little over a month prior, John Harold Rogers, a former senior advisor to the Federal Reserve Board of Governors, was sentenced to 38 months in prison for providing false statements to federal agents about sharing confidential monetary policy and Federal Open Market Committee details with Chinese state operatives. Rogers had been acquitted at trial on a separate charge of conspiracy to commit economic espionage.
Sources
Written by
The Company Wire
Inside the companies building what’s next. Reporting on startups, technology, funding and the people shaping them.

